CYBERSECURITYTRACKER
TRACKING6,660 stories in this site build1,369 vulnerability news stories in this site build

State now. Changed: +1 tier promotion, +1 known-exploited vulnerability addition, 15 leak-site claims, and 5 confirmed breaches since yesterday.

Why today matters · What to watch now

The latest security reporting, combined across sources and tagged, newest first

Reporting is aggregated from multiple sources. Anything Cybersecurity Tracker computes or infers is labelled as its own judgment, never as a claim made by a source. Stories are combined, de-duplicated, and tagged by category, vendor, and threat actor. Filter by your job role, follow the vendors you run, get the email digest, or subscribe by RSS. No account required.

Why now: this site build contains 6,660 stories, with the newest available reporting below.

Browse latest storiesSkip to latest stories
Filter by role (optional)

Showing: All categories

Details

Latest stories, newest first

Loading feed…
government policy

Supreme Court denies Trump request to allow USPS mail ballot changes

Source: CyberScoop.

The Supreme Court rejected a Trump administration petition to implement changes to U.S. Postal Service mail-in ballot handling for the 2026 midterm elections, ruling the proposed changes arbitrary and capricious. The rejected executive order would have tasked USPS with verifying voter citizenship and creating a barcode tracking system for mail ballot envelopes using Department of Homeland Security compiled citizenship lists. Lower courts had already blocked the order, and the justices found insufficient time for states to implement the rule before elections.

Why it matters: Election officials, voting infrastructure teams, and postal service administrators need to understand this decision blocks a significant change to mail ballot processes, preventing operational disruption and compliance conflicts just months before elections.

Tracker inference

vulnerabilitiesResearchCVE-2026-60163

CVE-2026-60163: MySQL Group Replication unauthenticated remote arbitrary SQL execution

Source: oss-security.

CVE-2026-60163 in MySQL Group Replication allows unauthenticated remote attackers to execute arbitrary SQL on destination systems. Oracle initially classified the attack vector as local but reclassified it to adjacent network following discussion, though the full attack surface may be remotely reachable in some configurations.

Why it matters: Database administrators managing MySQL Group Replication deployments must assess exposure to this unauthenticated remote code execution vulnerability and apply patches from Oracle immediately.

Tracker inference

ai security

No UK Regulators Can Stop Risky AI Models, Panel Warns

Source: HealthcareInfoSecurity.

British lawmakers identified a regulatory gap in which no United Kingdom regulator has authority to prevent the release of high-risk artificial intelligence (AI) models. The AI Security Institute lacks enforcement power to compel compliance or block deployments. Lawmakers are calling for new legislation to require the riskiest AI systems to clear regulatory approval before reaching the market.

Why it matters: Organizations operating in or subject to UK oversight face uncertainty about which AI systems will eventually be regulated; practitioners should monitor upcoming legislative proposals to understand future compliance requirements for model deployment and governance.

Tracker inference

ai security

AI CEOs Call for Slower Frontier Development as Stocks Fall

Source: HealthcareInfoSecurity.

Several artificial intelligence (AI) executives, including leaders from major AI labs, called for slowing frontier AI development, citing concerns about control of advanced AI systems. The statement triggered a decline in AI-related stock prices and drew criticism from the U.S. president.

Why it matters: AI practitioners and governance teams should monitor policy pressure from both industry and government that may shape development timelines, investment priorities, and safety investment at frontier labs.

Tracker inference

identity access

Cymphony Raises $30M to Turn Access Data Into Remediation

Source: HealthcareInfoSecurity.

Israeli identity and access security startup Cymphony raised $30 million in funding led by Sequoia Capital and SMBC Fin Atlas Beyond Fund. The company focuses on mapping identities, permissions, and activity to identify and remediate access-control weaknesses that attackers and artificial intelligence (AI) tools can exploit.

Why it matters: Security teams need visibility into dormant access permissions and risky identity configurations before attackers weaponize them; Cymphony's approach addresses the growing gap between privilege discovery and remediation as threats accelerate.

Tracker inference

cloud saas

Apple parental controls in iOS 27 let kids ask before opening new websites

Source: Help Net Security.

Apple released overhauled parental control features in iOS 27, iPadOS 27, and macOS 27 on September 14, 2026, built around a Child Account created through Family Sharing. The redesign follows a philosophy of starting with a restricted device and progressively opening capabilities as children demonstrate readiness, including a new feature allowing children to request permission before accessing unfamiliar websites.

Why it matters: Parents and device administrators managing child accounts need to evaluate the new parental controls to enforce appropriate usage policies, and app developers should understand how these restrictions may affect child users' ability to access their services.

Tracker inference

Cybersecurity jobs available right now: September 15, 2026

Source: Help Net Security.

A job board post lists open cybersecurity positions including an artificial intelligence (AI) and Security Architect role at SecNinjaz Technologies focused on designing secure AI agent platforms, and a Chief Information Security Officer (CISO) position at Texas Health and Human Services. The posts provide brief role descriptions and links to full job details.

Why it matters: Security practitioners and architects seeking employment opportunities can review open positions in AI security and healthcare cybersecurity leadership, with roles available in India and the United States.

Tracker inference

breaches incidents

Finnish Police Alert Europe Over Fugitive Vastaamo Hacker

Source: HealthcareInfoSecurity.

Finnish authorities issued a European Arrest Warrant for Aleksanteri Kivimäki, convicted for the Vastaamo breach, after he failed to return to prison. Kivimäki was responsible for stealing 33,000 psychotherapy records and extorting patients in one of Finland's most significant healthcare data breaches.

Why it matters: Healthcare organizations and their patients across Europe should be aware that the perpetrator of a major psychotherapy records theft remains at large, and law enforcement coordination may affect ongoing investigations or victim support efforts.

Tracker inference

regulatory

UK Panel Calls for Fresh Approach to Regulating Medical AI

Source: HealthcareInfoSecurity.

A UK government commission recommended a life-cycle risk-based regulatory approach for artificial intelligence (AI)-enabled medical devices and healthcare software, rather than relying solely on premarket reviews. The commission found that one-time approval models are insufficient as these technologies continue to evolve over time.

Why it matters: Medical device manufacturers, healthcare providers, and regulators need to understand the shift toward continuous monitoring and post-market oversight of AI systems, which will affect product development timelines, compliance costs, and market authorization strategies in the UK and potentially influence international regulatory trends.

Tracker inference

identity access

Beyond MFA: Protecting the Browser Session From Identity Attacks

Source: HealthcareInfoSecurity.

The article discusses security measures for protecting browser sessions against identity-based attacks beyond the use of multifactor authentication (MFA). It explores additional safeguards and techniques to defend authenticated sessions from compromise.

Why it matters: Security practitioners need to understand session protection strategies because MFA alone is insufficient; attackers exploit legitimate sessions through cookie theft, malware, and other post-authentication attacks that directly impact user accounts and organizational assets.

Tracker inference

identity access

When Access Reviews Aren’t Enough: Closing the Gaps in Identity Governance

Source: HealthcareInfoSecurity.

Access reviews alone cannot fully address identity governance challenges. Organizations must implement additional controls and processes to identify and remediate gaps in permission management across their systems.

Why it matters: Security practitioners need to understand that periodic access reviews are insufficient for preventing unauthorized access and must design layered identity governance strategies to reduce risk.

Tracker inference

threat intel

Seeing Isn’t Believing: The New Reality of Social Engineering

Source: HealthcareInfoSecurity.

The article carries a title about social engineering and perception but provides no substantive text or content to analyze.

Why it matters: Security practitioners need concrete examples, threat indicators, or actionable guidance to assess risk and implement defenses; this stub offers none.

Tracker inference

ot ics

When Cyberattacks Become Patient Safety Risks: How to Secure Healthcare’s Connected Devices

Source: HealthcareInfoSecurity.

Healthcare organizations face patient safety risks when cyberattacks target connected medical devices and systems. The article discusses the intersection of cybersecurity and clinical safety, highlighting how breaches can compromise device functionality and patient care delivery. Securing healthcare's connected infrastructure requires integrated approaches to both IT security and medical device safety.

Why it matters: Healthcare practitioners and IT teams must prioritize medical device security to prevent attacks that directly threaten patient outcomes and operational continuity.

Tracker inference

threat intel

'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink

Source: Dark Reading.

Sandworm, a Russian-linked threat group, is distributing an upgraded variant of Cyclops Blink botnet malware by exploiting Cisco vulnerabilities. The FBI previously disrupted the original botnet in 2022, but the group has rearmed with an enhanced version of the malware.

Why it matters: Organizations using Cisco devices are at immediate risk of botnet infection and remote compromise through this attack chain; patching affected Cisco products urgently is necessary to prevent exploitation.

Tracker inference

breaches incidents

Japan's Digital Agency says VPN flaw exposed 246,000 personnel records

Source: BleepingComputer.

Japan's Digital Agency discovered a data breach affecting approximately 246,000 records containing personal information of government employees. The incident involved a vulnerability in a virtual private network (VPN) system. The agency has confirmed the exposure of personnel data but the full scope and remediation timeline remain under investigation.

Why it matters: Government employees and contractors across Japan face identity theft and targeted social engineering risks; security teams should immediately audit VPN access logs and credential systems for signs of unauthorized access.

Tracker inference

industry2 sources

Homebrew 7.0.0 gets built-in GUI, better security controls

Sources: BleepingComputer and 1 more.

Homebrew package manager version 7.0.0 introduced a built-in vulnerability scanner, enhanced security controls, and released its native BrewUI graphical interface. The update brings improved tooling for users managing software dependencies on macOS and Linux systems.

Why it matters: Developers and DevOps teams using Homebrew should evaluate the new security scanner and controls to reduce supply chain risks in their build environments.

Tracker inference

vulnerabilities

In-the-Wild Attacks Hit Popular DevSecOps Platform GitLab

Source: HealthcareInfoSecurity.

Attackers are actively exploiting a recently patched vulnerability in self-hosted GitLab instances to steal files and credentials from public-facing servers. The vendor urges all self-hosted users to apply the patch immediately.

Why it matters: Organizations running self-hosted GitLab are at immediate risk of credential and source code theft; patches must be deployed without delay.

Tracker inference

ai security

Is Your Organization Mature Enough for AI?

Source: HealthcareInfoSecurity.

The CyberEdBoard will host a webinar on September 24 to present a maturity model developed by Carnegie Mellon's Software Engineering Institute and Accenture. The framework helps organizations evaluate their artificial intelligence (AI) adoption readiness and develop strategies for consistent, repeatable, and scalable outcomes.

Why it matters: Security leaders and enterprise architects need this maturity model to assess organizational readiness for AI deployment and identify capability gaps before investment.

Tracker inference

ot ics

Live Webinar | Securing the New Attack Surface: Defending Healthcare’s High-Leverage Cyber-Physical Systems (CPS)

Source: HealthcareInfoSecurity.

This is a webinar announcement about securing cyber-physical systems in healthcare environments. No substantive content or event details are provided.

Why it matters: Healthcare practitioners need to understand attack surface risks to critical infrastructure, but this stub offers no actionable findings or timelines.

Tracker inference

breaches incidents

Twitch extension with 30K installs exposes users’ OAuth tokens

Source: BleepingComputer.

A Twitch browser extension with 30,000 installations in official Chrome and Firefox stores transmits users' Twitch OAuth session tokens to an external commercial bot service. The extension, called Twitch Enhanced Viewer | JeetBot, exposes sensitive authentication credentials to unauthorized access.

Why it matters: Twitch users with this extension installed have their OAuth tokens exposed to a third party, enabling account takeover, unauthorized streaming, channel modifications, and credential compromise. Security teams should alert users to uninstall the extension and revoke Twitch OAuth tokens immediately.

Tracker inference

See what changed in the latest update.Looking further back? Browse the daily archive, this feed's own history.

How this is computed

Stories come from the published source set, are combined when reports cover the same event, and are ordered newest first. Trending uses the last 7 Coordinated Universal Time (UTC) calendar days, while the details feed states each story's published or first-seen date.

Method reviewed on .

Glossary